Web Application Enumeration Flashcards

1
Q

Cite two tools that are used for finding subdomains.

A

Assetfinder and Amass.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is HTTProbe?

A

It’s a tool used to test a domain list. It probes the list for working HTTP and HTTPS servers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Why is it a better practice to use different tools to look for subdomains?

A

Because each tool works in a different way, so combining their capabilities will probably return more results.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is subdomain takeover?

A

Subdomain takeover occurs when an attacker gains control over a subdomain of a target domain. Typically, this happens when a subdomain has a CNAME in DNS, but no host is providing content for it (The virtual host was removed or not yet deployed). So an attacker can provide his own virtual host and takeover that domain.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly